Altcoinbuzz
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Article Content
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart contracts, making it difficult for security teams to detect and remove. Victims are tricked into executing commands through fake CAPTCHA prompts on compromised websites. The malware primarily targets Windows systems, deploying information-stealing payloads like Lumma Stealer. The ClickFix campaign, linked to the ongoing ClearFake operation, has been confirmed to affect thousands of users daily. Microsoft advises users to avoid executing commands from CAPTCHA prompts and recommends organizations implement strict command-line controls. The campaign demonstrates the evolving tactics of cybercriminals leveraging blockchain technology to enhance malware delivery. This incident highlights the challenges of combating malware that utilizes decentralized infrastructure.
Key Points: • Cybercriminals are using EtherHiding on the BNB Smart Chain to deliver malware. • Victims are tricked into executing malicious commands via fake CAPTCHA prompts. • The ClickFix campaign is linked to the broader ClearFake malware operation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.